<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:33:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09234</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09234</link>
      <description>bdu:2026-09234</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09234</guid>
    </item>
    <item>
      <title>EUVD-2026-333756</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333756</link>
      <description>EUVD-2026-333756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333756</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22874</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22874</link>
      <description>&lt;p&gt;Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22874</guid>
    </item>
    <item>
      <title>GHSA-2r5c-gw76-rh3w — Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2r5c-gw76-rh3w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s default SSRF allow-list ([`MatchBuiltinExternal`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L26-L27), used by both webhook delivery and repository migrations) relies on Go&amp;#39;s standard library [`net.IP.IsPrivate()`](https://pkg.go.dev/net#IP.IsPrivate), which only covers RFC 1918 and RFC 4193. As a result, several IP ranges commonly used for cloud metadata services, internal networks, and IPv6 transition mechanisms are not blocked, allowing authenticated users to send HTTP requests to those destinations and read the responses via the webhook history UI.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability lives in [`HostMatchList.checkIP`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L96-L114), specifically [line 103](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L103):&lt;/p&gt;
&lt;p&gt;```go
case MatchBuiltinExternal:
    if ip.IsGlobalUnicast() &amp;amp;&amp;amp; !ip.IsPrivate() {
        return true
    }
```&lt;/p&gt;
&lt;p&gt;`net.IP.IsPrivate()` recognises only:
- `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16` (RFC 1918)
- `fc00::/7` (RFC 4193 IPv6 ULA)&lt;/p&gt;
&lt;p&gt;It does **not** recognise:&lt;/p&gt;
&lt;p&gt;| Range | Description |
|---|---|
| `100.64.0.0/10` | RFC 6598 Carrier-Grade NAT |
| `168.63.129.16/32` | Azure WireServer metadata endpoint |
| `172.32.0.0/11` | Non-RFC1918 portion of `172.0.0.0/8` (real-world internal use) |
| `64:f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.gitea.io/gitea&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Gitea&amp;#39;s default SSRF allow-list ([`MatchBuiltinExternal`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L26-L27), used by both webhook delivery and repository migrations) relies on Go&amp;#39;s standard library [`net.IP.IsPrivate()`](https://pkg.go.dev/net#IP.IsPrivate), which only covers RFC 1918 and RFC 4193. As a result, several IP ranges commonly used for cloud metadata services, internal networks, and IPv6 transition mechanisms are not blocked, allowing authenticated users to send HTTP requests to those destinations and read the responses via the webhook history UI.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability lives in [`HostMatchList.checkIP`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L96-L114), specifically [line 103](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L103):&lt;/p&gt;
&lt;p&gt;```go
case MatchBuiltinExternal:
    if ip.IsGlobalUnicast() &amp;amp;&amp;amp; !ip.IsPrivate() {
        return true
    }
```&lt;/p&gt;
&lt;p&gt;`net.IP.IsPrivate()` recognises only:
- `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16` (RFC 1918)
- `fc00::/7` (RFC 4193 IPv6 ULA)&lt;/p&gt;
&lt;p&gt;It does **not** recognise:&lt;/p&gt;
&lt;p&gt;| Range | Description |
|---|---|
| `100.64.0.0/10` | RFC 6598 Carrier-Grade NAT |
| `168.63.129.16/32` | Azure WireServer metadata endpoint |
| `172.32.0.0/11` | Non-RFC1918 portion of `172.0.0.0/8` (real-world internal use) |
| `64:f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2r5c-gw76-rh3w</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2027 — Gitea: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2027</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um erweiterte Berechtigungen zu erlangen, sich als Benutzer auszugeben, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um erweiterte Berechtigungen zu erlangen, sich als Benutzer auszugeben, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2027</guid>
    </item>
  </channel>
</rss>
